As you pointed out, it is likely missing in the mappings: https://github.com/elastic/integrations/blob/master/packages/osquery_manager/data_stream/result/fields/osquery.yml
@aleksmaus To not have to map all fields, maybe a dynamic mapping that matches *.ip could be used?